HomeGlossaryCybersecurity Maturity Model Certification (CMMC)
Compliance & SecurityCMMC

Cybersecurity Maturity Model Certification (CMMC)

CMMC is the DoD's mandatory cybersecurity certification framework requiring defense contractors to demonstrate compliance with NIST security controls before receiving contracts.

Quick answer

CMMC is the DoD's mandatory cybersecurity certification framework requiring defense contractors to demonstrate compliance with NIST security controls before receiving contracts.


Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense's mandatory cybersecurity compliance framework requiring defense contractors and subcontractors to achieve and verify specific cybersecurity control implementation levels before being eligible for DoD contract awards.

What is CMMC?

CMMC was developed by the Office of the Under Secretary of Defense for Acquisition and Sustainment in response to persistent and escalating cyber threats targeting the Defense Industrial Base (DIB). The framework operationalizes existing cybersecurity requirements in DFARS 252.204-7012 and aligns with NIST SP 800-171 controls, adding a formal assessment and certification layer to what had previously been a self-attestation regime.

CMMC 2.0 - the current version as of 2026 - establishes three certification levels. Level 1 covers 17 basic cybersecurity practices aligned with FAR 52.204-21 and applies to contractors handling only Federal Contract Information (FCI). Self-assessment is permitted. Level 2 covers 110 security practices aligned with NIST SP 800-171 and applies to contractors handling Controlled Unclassified Information (CUI). Level 2 requires either a triennial third-party assessment by a CMMC Third-Party Assessment Organization (C3PAO) for prioritized acquisitions, or annual self-assessment for non-prioritized acquisitions. Level 3 covers 134+ practices aligned with NIST SP 800-172 and applies to contractors on the most sensitive DoD programs. Level 3 requires a Defense Contract Management Agency (DCMA) DIBCAC assessment.

CMMC requirements flow down through the supply chain. A prime contractor awarded a contract requiring Level 2 certification must also ensure that subcontractors handling CUI achieve the required certification level. This flow-down obligation means subcontractors in the defense supply chain are affected by CMMC even when they do not contract directly with DoD.

Why CMMC matters for government contractors

CMMC is not optional for companies pursuing DoD contracts involving CUI. As CMMC requirements are phased into contract solicitations - a process the DoD began implementing in 2025 - companies without the required certification level will be ineligible to receive awards. The certification process is time-consuming and expensive: Level 2 C3PAO assessments can take six to twelve months to complete and cost $50,000 to $150,000 or more depending on company size and the maturity of existing controls. Companies that have not begun their CMMC journey are at risk of losing DoD contract eligibility as requirements fully roll out. Read more about CMMC compliance for defense contractors.

Example

A small defense IT firm with 85 employees holds three DoD contracts under which it develops software that processes CUI. The firm's ISSO conducts a gap assessment against the 110 NIST SP 800-171 controls and identifies 22 controls that need remediation - primarily around multi-factor authentication, log monitoring, and incident response. The firm engages a CMMC Registered Practitioner Organization (RPO) for remediation assistance, implements the missing controls over eight months, and then engages a C3PAO for a formal Level 2 assessment. The assessment finds all 110 controls implemented and issues a Certificate of Final Assessment (CFA). The firm now meets the CMMC Level 2 requirement and can respond to solicitations specifying Level 2 certification.

Frequently Asked Questions

When do CMMC requirements appear in DoD solicitations?


DoD began phasing CMMC requirements into solicitations starting in fiscal year 2025. The phase-in follows a rulemaking process under DFARS, with requirements initially applied to higher-priority programs and expanding over time. Contractors should monitor DFARS updates and specific solicitations to understand when CMMC requirements apply to their target opportunities.

Does CMMC apply to subcontractors?


Yes. CMMC requirements flow down to subcontractors at any tier that handle CUI relevant to the contract. Prime contractors are responsible for ensuring that their subcontractors handling CUI meet the required CMMC level. This flow-down obligation is included in prime contract clauses that subcontractors must accept. Subcontractors should assess their CMMC requirements in consultation with primes and the specific contract requirements.

Can a company self-certify for Level 2?


For non-prioritized Level 2 acquisitions, annual self-assessment and affirmation by a senior company official are accepted. For prioritized acquisitions - those involving critical programs or heightened CUI sensitivity - a third-party assessment by a C3PAO is required. DoD determines which acquisitions are prioritized. Companies cannot choose which path to use based on preference; the solicitation specifies the required assessment path.

What is a C3PAO and how do I find one?


A C3PAO (CMMC Third-Party Assessment Organization) is an organization authorized by the CMMC Accreditation Body (Cyber AB) to conduct Level 2 assessments. The Cyber AB maintains a marketplace of authorized C3PAOs at cyberAB.org. Companies seeking Level 2 certification contract directly with a C3PAO for their assessment. C3PAOs are independent of the DoD and charge market rates for assessment services.

How Bidovate helps

Bidovate puts Cybersecurity Maturity Model Certification (CMMC) to work inside your capture and proposal workflow.

Federal contracting

See Bidovate in action

Book a demo and we will show you the platform using your actual contract data.